Files
republic-os/legal/us/code/title-15/chapter-7/section-278g-3e.md
T
Fabio 76b8ec33a7 Legal corpus: the complete U.S. Code (59,740 sections, all 53 titles)
Ingested titles 12–51 and 54 from OLRC USLM XML @119-100 (the whole Code
now, uniform edition; Title 53 is reserved/empty). LegalText 11,221 ->
59,740; repo total 105,704 records. Deterministic (byte-identical rerun,
verified on Title 42's 8,356 sections); make check green. make
legal-us-code default now covers every title.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 10:51:44 -04:00

4.6 KiB
Raw Blame History

type, title, description, jurisdiction, corpus, kind, title_number, title_name, chapter_number, chapter_name, section, citation, status, release_point, release_date, source, source_url, source_identifier, source_file, source_hash, raw_snapshot_hash, text_hash, retrieved_at, confidence, tags
type title description jurisdiction corpus kind title_number title_name chapter_number chapter_name section citation status release_point release_date source source_url source_identifier source_file source_hash raw_snapshot_hash text_hash retrieved_at confidence tags
LegalText 15 U.S.C. § 278g3e Contractor compliance with coordinated disclosure of security vulnerabilities relating to agency Internet of Things devices us united_states_code code_section 15 COMMERCE AND TRADE 7 NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY 278g3e 15 U.S.C. § 278g3e current 119-100 2026-06-26 official https://uscode.house.gov/download/releasepoints/us/pl/119/100/xml_usc15@119-100.zip /us/usc/t15/s278g3e data/legal/raw/us/code/title-15/usc15.xml c109c30b17edb7379711a6ffe36ecc32e347bccb81a1ed5e7441d70237501782 6982338d990ef19d6b52bff6825089bdd6d0ee1233d9382673faf533decd5059 6e547c152c5a93b37843ca51b043ca1c4ba0614db26663eadf81b49707907c1c 2026-07-04 official
legal
us-code

15 U.S.C. § 278g3e - Contractor compliance with coordinated disclosure of security vulnerabilities relating to agency Internet of Things devices

Text

(a) Prohibition on procurement and use (1) In general The head of an agency is prohibited from procuring or obtaining, renewing a contract to procure or obtain, or using an Internet of Things device, if the Chief Information Officer of that agency determines during a review required by section 11319(b)(1)(C) of title 40 of a contract for such device that the use of such device prevents compliance with the standards and guidelines developed under section 278g3b of this title or the guidelines published under section 278g3c of this title with respect to such device.

(2) Simplified acquisition threshold Notwithstanding section 1905 of title 41, the requirements under paragraph (1) shall apply to a contract or subcontract in amounts not greater than the simplified acquisition threshold.

(b) Waiver (1) Authority The head of an agency may waive the prohibition under subsection (a)(1) with respect to an Internet of Things device if the Chief Information Officer of that agency determines that—

(A) the waiver is necessary in the interest of national security;

(B) procuring, obtaining, or using such device is necessary for research purposes; or

(C) such device is secured using alternative and effective methods appropriate to the function of such device.

(2) Agency process The Director of OMB shall establish a standardized process for the Chief Information Officer of each agency to follow in determining whether the waiver under paragraph (1) may be granted.

(c) Reports to Congress (1) Report Every 2 years during the 6-year period beginning on December 4, 2020, the Comptroller General of the United States shall submit to the Committee on Oversight and Reform of the House of Representatives, the Committee on Homeland Security of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs of the Senate a report—

(A) on the effectiveness of the process established under subsection (b)(2);

(B) that contains recommended best practices for the procurement of Internet of Things devices; and

(C) that lists—

(i) the number and type of each Internet of Things device for which a waiver under subsection (b)(1) was granted during the 2-year period prior to the submission of the report; and

(ii) the legal authority under which each such waiver was granted, such as whether the waiver was granted pursuant to subparagraph (A), (B), or (C) of such subsection.

(2) Classification of report Each report submitted under this subsection shall be submitted in unclassified form, but may include a classified annex that contains the information described under paragraph (1)(C).

(d) Effective date The prohibition under subsection (a)(1) shall take effect 2 years after December 4, 2020.

(Pub. L. 116207, § 7, Dec. 4, 2020, 134 Stat. 1005.)

Notes

Editorial Notes

Codification Section was enacted as part of the Internet of Things Cybersecurity Improvement Act of 2020, also known as the IoT Cybersecurity Improvement Act of 2020, and not as part of the National Institute of Standards and Technology Act which comprises this chapter.

Statutory Notes and Related Subsidiaries

Change of Name Committee on Oversight and Reform of House of Representatives changed to Committee on Oversight and Accountability of House of Representatives by House Resolution No. 5, One Hundred Eighteenth Congress, Jan. 9, 2023.

Definitions For definitions of terms used in this section, see section 278g3a of this title.